2024-12-12 21:07:30 +00:00

234 lines
10 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20193045",
"Version": "oval:org.altlinux.errata:def:20193045",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-3045: package `chromium` update to version 77.0.3865.120-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit",
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-3045",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-3045",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01604",
"RefURL": "https://bdu.fstec.ru/vul/2020-01604",
"Source": "BDU"
},
{
"RefID": "BDU:2020-01605",
"RefURL": "https://bdu.fstec.ru/vul/2020-01605",
"Source": "BDU"
},
{
"RefID": "BDU:2020-01779",
"RefURL": "https://bdu.fstec.ru/vul/2020-01779",
"Source": "BDU"
},
{
"RefID": "BDU:2020-01780",
"RefURL": "https://bdu.fstec.ru/vul/2020-01780",
"Source": "BDU"
},
{
"RefID": "BDU:2020-01781",
"RefURL": "https://bdu.fstec.ru/vul/2020-01781",
"Source": "BDU"
},
{
"RefID": "CVE-2019-13693",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-13693",
"Source": "CVE"
},
{
"RefID": "CVE-2019-13694",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-13694",
"Source": "CVE"
},
{
"RefID": "CVE-2019-13695",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-13695",
"Source": "CVE"
},
{
"RefID": "CVE-2019-13696",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-13696",
"Source": "CVE"
},
{
"RefID": "CVE-2019-13697",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-13697",
"Source": "CVE"
}
],
"Description": "This update upgrades chromium to version 77.0.3865.120-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01604: Уязвимость реализации протокола WebRTC браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность\n\n * BDU:2020-01605: Уязвимость встроенной базы данных IndexedDB браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность\n\n * BDU:2020-01779: Уязвимость браузера Google Chrome, связанная с использованием памяти после освобождения, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность\n\n * BDU:2020-01780: Уязвимость обработчика JavaScript-сценариев браузера Google Chrome, связанная с использованием памяти после освобождения, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность\n\n * BDU:2020-01781: Уязвимость браузера Google Chrome, связанная с неправильным контролем доступа к критическому ресурсу, позволяющая нарушителю получить несанкционированный доступ\n\n * CVE-2019-13693: Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.\n\n * CVE-2019-13694: Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\n\n * CVE-2019-13695: Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\n\n * CVE-2019-13696: Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\n\n * CVE-2019-13697: Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-10-23"
},
"Updated": {
"Date": "2019-10-23"
},
"BDUs": [
{
"ID": "BDU:2020-01604",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2020-01604",
"Impact": "High",
"Public": "20191022"
},
{
"ID": "BDU:2020-01605",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2020-01605",
"Impact": "High",
"Public": "20191022"
},
{
"ID": "BDU:2020-01779",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2020-01779",
"Impact": "High",
"Public": "20191125"
},
{
"ID": "BDU:2020-01780",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2020-01780",
"Impact": "High",
"Public": "20191125"
},
{
"ID": "BDU:2020-01781",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-732",
"Href": "https://bdu.fstec.ru/vul/2020-01781",
"Impact": "Low",
"Public": "20191125"
}
],
"CVEs": [
{
"ID": "CVE-2019-13693",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-13693",
"Impact": "High",
"Public": "20191125"
},
{
"ID": "CVE-2019-13694",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-13694",
"Impact": "High",
"Public": "20191125"
},
{
"ID": "CVE-2019-13695",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-13695",
"Impact": "High",
"Public": "20191125"
},
{
"ID": "CVE-2019-13696",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-13696",
"Impact": "High",
"Public": "20191125"
},
{
"ID": "CVE-2019-13697",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-209",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-13697",
"Impact": "Low",
"Public": "20191125"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:container:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20193045001",
"Comment": "chromium is earlier than 0:77.0.3865.120-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193045002",
"Comment": "chromium-gnome is earlier than 0:77.0.3865.120-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193045003",
"Comment": "chromium-kde is earlier than 0:77.0.3865.120-alt1"
}
]
}
]
}
}
]
}